A question comes up early in almost every conversation about export-controlled engineering work: we are subject to export controls, so which cybersecurity framework do we have to follow? It is the right question. The difficulty is that the answer is not in the export regulation, and people go looking for it there.
10 CFR Part 810 is the clearest illustration available. It is the Department of Energy rule governing assistance to foreign atomic energy activities — the transfer of unclassified nuclear technology, whether abroad or to a foreign national standing in a room in the United States. It carries civil and criminal penalties. It is unambiguously a regulation about controlling sensitive information. And it contains no cybersecurity requirements at all.
What Part 810 Actually Says
Part 810 implements section 57 b.(2) of the Atomic Energy Act, codified at 42 U.S.C. 2077.1 Its structure is straightforward. Section 810.2(b) lists the activities within scope. Section 810.6 makes certain activities generally authorized where the destination appears in Appendix A. Section 810.7 requires case-by-case authorization from the Secretary in three situations: activities with a country or entity not on the Appendix A list; the transfer of sensitive nuclear technology to any foreign country or entity at all; and a list of specified activities including uranium and plutonium isotope separation, heavy water production, production reactors, and reprocessing of irradiated fuel.2
The definitions matter more than they usually do. Section 810.3 defines a foreign national as someone who is not a citizen or national of the United States, but excludes lawful permanent residents and protected individuals under 8 U.S.C. 1324b(a)(3). That is narrower than the phrase most companies use in practice, and an access rule written around “U.S. persons” will not match the regulation it is meant to enforce. The same section defines technical data to include information recorded on disks, tapes, read-only memories, and computer codes — so there is no argument that the regulation was written for paper and never contemplated systems.3
Section 810.12 requires reports. Section 810.15 provides for penalties: criminal exposure under section 222 of the Atomic Energy Act, and, since a 2023 rulemaking, civil monetary penalties now set at $127,973 per violation, applied per day where a violation is a continuing one, and adjusted annually for inflation.4
Now the part that does not exist. Read the regulation in full, and read the 2015 final rule that produced its current form. The words cybersecurity, information security, and encryption do not appear. Not once, in either.5
What Part 810 says about protecting the technology it controls amounts to two things. Section 810.6(b) generally authorizes certain transfers to a foreign national where that person “executes a confidentiality agreement with the U.S. employer to safeguard the technology from unauthorized use or disclosure.” And section 810.11(b) requires an applicant for specific authorization to describe “the applicant’s technology control program” — a term the regulation uses and never defines. There is no list of elements. No requirement for access control, audit logging, encryption, network segmentation, or any other technical measure. DOE and NNSA guidance materials on Part 810 describe authorization mechanics and confidentiality agreements; they do not prescribe an information-security standard either.
A regulation can tell you that your information is controlled, that transferring it without permission is a crime, and that violations cost $127,973 apiece — and never once tell you what to build.
Two Other Export Rules Address Encryption. This One Does Not.
This is worth dwelling on, because most firms handling controlled technical data have absorbed a rule of thumb from elsewhere in the export-control world, and it does not transfer.
The International Traffic in Arms Regulations contain section 120.54, which lists activities that are not exports. Among them: sending, taking, or storing technical data that is unclassified, secured end-to-end, and secured using cryptographic modules compliant with FIPS 140-2 or by other means providing security strength at least comparable to 128-bit AES — provided the data is not intentionally sent to or stored in a country listed in section 126.1, or in Russia. The provision goes further and says that the ability to access technical data in encrypted form that meets those criteria does not constitute a release or export of that data.6
The Export Administration Regulations contain the same architecture at section 734.18, which was the earlier of the two and served as the model.7
Part 810 has no equivalent. There is no provision stating that encrypting controlled nuclear technology means a transfer has not occurred. There is no DOE guidance saying so either. The practical consequence is direct: a company can encrypt nuclear technology to a FIPS-validated standard, which is prudent and which will help it satisfy obligations that come from elsewhere, and it will not have earned the regulatory safe harbor that the same encryption would earn under the ITAR or the EAR. This finding rests on the absence of a provision rather than the presence of one, and it is stated on that basis.
So Where Does the Control Set Come From?
Through the Controlled Unclassified Information framework, in five steps. Each step has an authority behind it.
One. Executive Order 13556 created a government-wide program for unclassified information that laws, regulations, and government-wide policies require to be protected.8
Two. The National Archives issued the implementing rule at 32 CFR Part 2002. It distinguishes CUI Basic, where the underlying authority sets no particular controls, from CUI Specified, where the authority prescribes its own. And it states that NIST SP 800-171 defines the requirements for protecting CUI Basic on non-federal information systems.9
Three. The CUI Registry contains a category called Export Controlled. Its description covers information whose export could reasonably be expected to affect national security and nonproliferation objectives — and it names, expressly, sensitive nuclear technology information. Among the authorities listed for that category is 42 U.S.C. 2077(a): the same statute Part 810 implements, designated as a Specified authority and carrying the marking CUI//SP-EXPT.10
Four. CUI Specified means you follow the safeguarding requirements the underlying law prescribes. Part 810 prescribes none.
Five. Where a Specified authority is silent on safeguarding, the CUI Basic controls apply. Those controls are NIST SP 800-171 — 110 requirements across 14 families in Revision 2, which remains the revision the Department of Defense enforces.11
So the chain runs from a nuclear export regulation that says nothing about cybersecurity, through a records-management executive order, to a NIST publication. Nothing in that chain is obscure. It is simply spread across four documents that nobody reads together.
The Part Most People Get Wrong
Here is where the common account fails. It is usually stated as: the data is export-controlled, therefore it is CUI, therefore 800-171 applies. Each arrow in that sentence is doing work the regulation does not support.
The CUI rule binds executive branch agencies. It reaches a company through an agreement — a contract, grant, license, or similar instrument. And the definition is explicit about the boundary. CUI does not include information that a non-executive-branch entity “possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency.”9
Read that against a real situation. A company designs equipment on its own money, for a commercial customer, using its own engineers. The design information is squarely export-controlled — Part 810 applies to it, and transferring it to a foreign national without authorization is unlawful. But it did not come from a federal agency and was not created for one. It is not CUI, and no federal cybersecurity standard is legally imposed on it.
Change one fact. The same company performs the same work under a subcontract to a national laboratory operator, and the prime flows down DFARS 252.204-7012 or an equivalent DOE clause. Now the information sits inside a federal agreement, the CUI framework reaches it, and NIST SP 800-171 is contractually mandatory.
Same engineering. Same file. Same server. Different obligation — because the contract changed, not because the data did.
Your export-control obligation follows the technology. Your cybersecurity obligation follows the contract. They are different questions with different answers, and conflating them produces error in both directions.
Both directions is the point. Firms over-scope, building to a certification standard nothing in their contract requires, and paying for it. Firms under-scope, reasoning that they hold no direct federal contract and therefore owe nothing, and missing a flow-down sitting in a subcontract nobody read. The first mistake costs money. The second costs eligibility, and can cost considerably more than that.
One further distinction is worth keeping straight, because the terms sound interchangeable and are not. The CUI Registry also carries nuclear-specific categories — Unclassified Controlled Nuclear Information under 42 U.S.C. 2168, and Naval Nuclear Propulsion Information — which rest on different statutes and protect different information, principally facility and material security data rather than design and manufacturing technology.12 Sensitive nuclear technology under Part 810 travels through the Export Controlled category. Both are CUI. They arrive by different routes and can carry different handling requirements.
What This Looks Like Across the Regimes You Might Touch
| Regime | What it controls | Prescribes a control set? | Where the control set comes from |
|---|---|---|---|
| 10 CFR Part 810 DOE / NNSA | Transfer of unclassified nuclear technology and assistance, including to foreign nationals inside the U.S. | No | CUI framework plus a federal contract |
| ITAR State / DDTC | Defense articles and technical data on the U.S. Munitions List | No control set, but § 120.54 defines an encryption safe harbor | CUI framework plus a contract; encryption standard self-contained for the carve-out |
| EAR Commerce / BIS | Dual-use items and technology; nuclear end-use restrictions at § 744.2; 0-series ECCNs | No control set, but § 734.18 defines an encryption safe harbor | CUI framework plus a contract |
| 10 CFR Part 110 NRC | Export and import of nuclear equipment and material — hardware, not technology | No | Not an information-security regime |
| DFARS 252.204-7012 | Safeguarding covered defense information; 72-hour incident reporting | Yes, by reference | NIST SP 800-171, imposed by contract clause |
| FAR 52.204-21 now 52.240-93 | Basic safeguarding of federal contract information | Yes | Fifteen requirements, self-contained |
| CMMC 32 CFR Part 170 | Verification that a contractor meets 800-171 | Adopts 800-171; adds assessment | NIST SP 800-171 — a verification layer, not the source of the duty |
| DOE contractor requirements | Protection of CUI and UCNI on contractor systems | Yes, by contract and directive | DEAR clauses and DOE orders |
Read down the third column. Only the contract clauses prescribe anything. Every export regulation in the table controls information without specifying how to secure it.
The July Suspension Proved the Point
On 13 July 2026 the Department of War suspended CMMC Phase II, the third-party certification layer that was to begin appearing in contracts on 10 November 2026.13 The suspension was announced alongside a sixty-day review, and it changed nothing about what contractors owe. DFARS 252.204-7012 continued. NIST SP 800-171 Revision 2 continued. Self-assessment and SPRS scoring continued. The annual affirmation at 32 CFR 170.22 continued.14 That was the subject of the companion assessment in this series.15
Set against the structure described above, the reason is plain rather than surprising. CMMC was never the source of the obligation. It was a mechanism for checking whether the obligation had been met. The duty itself sits in the contract clause, and behind the clause in the CUI framework, and behind that in a NIST publication. Removing the verification layer left the obligation layer untouched because they were never the same layer.
The same logic runs one step further. A regulation that never prescribed a control set cannot lose one when a certification program pauses. Whatever the Task Force recommends in September will change what contracts require going forward. It will not change what Part 810 says, because Part 810 never said anything on the subject.
Nobody Has Ever Been Fined Under Part 810
There is an asymmetry here that is worth stating plainly, because it runs against intuition.
Part 810 carries real penalties. DOE finalized the civil penalty procedures in a rule effective February 2023, and the maximum now stands at $127,973 per violation.4 Yet no assessed civil penalty under Part 810 appears anywhere in the public record — not in DOE or NNSA announcements, not in the Federal Register, not in the trackers that law firms maintain for exactly this purpose. The leading criminal matter under section 57 predates the civil penalty rule: Szuhsiung Ho pleaded guilty in 2017 and received twenty-four months.16 Part 810 enforcement records are not always public, so absence of a published penalty is strong evidence rather than proof.
Now look at the other side. In fiscal year 2025 the Department of Justice reported more than $52 million recovered across nine cybersecurity settlements under the False Claims Act, and has settled fifteen such matters since the Civil Cyber-Fraud Initiative began in 2021.17 Georgia Tech Research Corporation paid $875,000 in September 2025 over an allegedly fictitious assessment environment and a campus-wide score DOJ called false.18 In June 2026 a Huntsville contractor paid $507,144 after self-reporting a perfect score of 110 and later being assessed by the government at negative 170.19
So the export regulation that controls nuclear technology and carries six-figure penalties has, so far as the public record shows, never assessed one. The contract clause that says nothing about nuclear technology at all is where the enforcement actually happens. If you are budgeting attention by where the risk has historically landed, it lands on the representation you made in a federal contract — not on the export rule that made your data sensitive in the first place.
Three Questions That Settle It for Your Company
None of these requires counsel to answer, though the answers may send you to counsel.
One. Where did this information come from? Did it originate with a federal agency, or was it created for one under a contract, grant, or other agreement? If neither — if your engineers made it on company money for a commercial customer — it may be export-controlled without being CUI, and no federal cybersecurity standard is legally imposed on it.
Two. If there is a federal agreement, what clause is in it? Not what your customer said on a call. The clause list in the contract. Look for DFARS 252.204-7012, for FAR 52.204-21 or its renumbered form at 52.240-93, and for DOE equivalents. The clause is what creates the obligation, and it is a document you already hold.20
Three. If a customer is asking you to become compliant, what exactly are they citing? Get it in writing. A customer requirement that names NIST SP 800-171 Revision 2 sets a different target than one demanding a government-cloud environment or third-party certification. Building to the wrong assumption is expensive, and the language costs nothing to obtain.
If those three answers are clear and consistent, the framework question resolves itself. If they conflict — a prime demanding certification under a contract carrying no such clause, say — that conflict is the finding, and it is better identified before an environment is built around it.
When This Stops Being a Technical Question
Whether particular technology falls within Part 810’s scope, whether a transfer requires specific authorization, and who a company designates as its empowered official are legal determinations. So is any conclusion that a representation already made to the government may have been inaccurate. Those belong with export-control counsel, and the second belongs there immediately.
What is engineering, and what this assessment addresses, is the question of which control set a system should be built to and why. That question has an answer, and the answer is not in the export regulation.
This assessment is not legal advice and is not a substitute for counsel.